Skip to content
compliancebase

Theme comparison · soc-2-type

SOC 2 Type I vs Type II

What differs between SOC 2 Type I (design) and Type II (operating effectiveness over a period) — evidence, timeline, buyer expectations, and when each makes sense.

Frameworks covered: SOC 2

Key differences

DimensionType IType II
What is evaluatedSuitability of control design at a point in time — the auditor opines on whether controls are suitably designed as of the report date, not whether they operated consistently beforehand.Design plus operating effectiveness over a defined observation period — the auditor tests whether controls operated as described throughout the window, not only on a single day.
Evidence emphasisPolicies, configurations, architecture diagrams, and walkthroughs as of the report date; limited need for populations spanning months.Complete populations, samples, timestamps, and logs spanning the full observation window — access reviews, change tickets, incident records, and similar recurring evidence must cover the period cleanly.
Typical buyer preferenceUseful early signal of design readiness; often treated as interim by enterprise procurement and rarely sufficient alone for mature security questionnaires.Default ask for B2B SaaS security reviews — most enterprise RFPs and vendor risk teams expect a recent Type II covering Security (and any other categories in scope).
TimelineFaster to reach if controls are designed and evidenced as of a date but have not yet operated long enough for a Type II window.Requires months of clean, continuous operation (commonly 3–12 months). The clock starts when controls are live and evidence collection is reliable — not when you first talk to an auditor.
Cost / auditor effortLower fieldwork effort generally — fewer samples and less period testing, though scoping and system description work still matter.Higher — testing over time increases sample sizes, evidence requests, and iteration on exceptions found during the period.
Bridge to next reportOften followed soon by Type II; buyers may treat Type I as a short-lived milestone rather than a durable vendor-risk artifact.Annual Type II cadence is typical, with optional bridge/comfort letters covering the gap between report date and the next report’s availability.

Control overlap

The underlying AICPA Trust Services Criteria and the control set you design against are the same family for Type I and Type II. You do not implement a different CC6 or CC8 control catalog for each report type. What changes is the nature and period of CPA testing: Type I focuses on design suitability as of a date; Type II adds operating-effectiveness testing across an observation window. Policies, system description, and control owners should be built once for continuous operation — not rewritten when you move from Type I to Type II.

Sequencing advice

If target buyers already require Type II, go straight to Type II and avoid paying for two fieldwork cycles. Use Type I when you need an earlier attestation of design readiness (fundraising, early enterprise pilots, or a board milestone) while the Type II observation window accumulates. Either path depends on the same foundation: documented controls, an accurate system description, and continuous evidence so the Type II period is not a scramble of backfilled tickets. Confirm period length and report-use expectations with your auditor and a sample of key customers before locking the engagement letter.

Frequently Asked Questions

No. Many organizations begin with Type II once controls have operated long enough. Type I is optional and situational — useful when you need an earlier design attestation, but not a prerequisite in the AICPA standards or most enterprise procurement playbooks.

Commonly 3–12 months. Longer periods can increase buyer confidence; shorter periods may be accepted for a first report if customers and your CPA firm agree. Confirm period length in the engagement letter and with target customers before you start the observation window.

Some will as an interim artifact while Type II evidence accumulates. Many enterprise questionnaires explicitly ask for Type II covering a recent period, so treat Type I as a bridge, not a permanent substitute, unless your specific buyers say otherwise in writing.

Usually yes, because auditors test operating effectiveness over time — more samples, more evidence requests, and more follow-up on exceptions. See /costs/soc-2/type-2 for indicative ranges; actual fees depend on scope, categories, and readiness.

A letter from management (sometimes with auditor involvement per firm practice) covering the period after a report date until a newer report is available. It can ease vendor-risk timing gaps but does not replace a Type II report or assert operating effectiveness the way a full examination does.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above